PT-2026-61226 · Linux · Linux
CVE-2026-63909
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: OOB read regression in smb check perm dacl() ACE-walk loops
Commit d07b26f39246 ("ksmbd: require minimum ACE size in
smb check perm dacl()") introduced a transposed bounds check:
if (offsetof(struct smb ace, sid) + aces size < CIFS SID BASE SIZE)
Since offsetof(..sid) is 8 and CIFS SID BASE SIZE is 8, this evaluates
to
aces size < 0. Because aces size is always non-negative, this
check becomes dead code and never breaks the loop.Worse, that commit removed the old 4-byte guard, meaning the loop now
reads
ace->size (offset 2) even when aces size is 0-3 bytes. This
re-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation
during subsequent SMB2 CREATE operations.Fix this by properly transposing the comparison to require at least
16 bytes (8-byte offset + 8-byte SID base), matching the correct form
used in smb inherit dacl().
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux